Team & roles
Invite collaborators and assign granular permissions to secure access to your account.
6 min read
Manage who accesses your Wajub account and with which rights under Settings → Team.
Built-in roles
OwnerroleoptionalFull control, including billing and account deletion. Single owner only.
AdminroleoptionalManages team, API keys, and settings. Not billing.
DeveloperroleoptionalAccess to test keys, Konsole, and webhooks. No access to funds.
FinanceroleoptionalTransfers, refunds, reports, and settlements.
SupportroleoptionalRead-only access to transactions and customers, without sensitive operations.
Inviting a member
Enter the email, choose the role, send the invitation. The member joins after accepting and configuring two-factor authentication.
Security
Principle of least privilege
Assign the most restrictive role that is sufficient. Reserve Finance for people who need to move funds, and Developer without production access until the integration is validated.
- Mandatory 2FA can be enforced for the entire team.
- Audit log: every sensitive action (key rotation, transfer, role change) is timestamped and attributed to a member.
- Revoke access instantly; associated sessions and keys are invalidated.